Name:Windows Alternate Data Stream Created Over Local Share id:e974a5c9-cbe9-4b4a-8fba-b55e7dbc8259 version:2 date:None author:Onur Mustafa Erdogan, Splunk status:production type:Anomaly Description:The following analytic detects the creation of an NTFS alternate data stream (ADS) accessed over a local administrative share targeting the loopback address (127.0.0.1).
It leverages Windows Security Event Logs with EventCode 5145 to identify this activity.
Legitimate local processes access files directly rather than through a local SMB share.
This behavior is a hallmark of the ShieldBreak exploit, which abuses a symbolic link swap through a loopback share to redirect a privileged, Defender-driven write into an alternate data stream on a system-owned file, ultimately landing attacker content in C:\Windows\System32.
If confirmed malicious, this activity indicates an in-progress local privilege escalation attempt and should be investigated immediately. Data_source:
-Windows Event Log Security 5145
search:`wineventlog_security` EventCode=5145 IpAddress IN ("127.0.0.1", "::1") ObjectType="File" | regex RelativeTargetName="(?i)\:\w+$" | fillnull | rename IpAddress as dest_ip | stats count min(_time) as firstTime max(_time) as lastTime by dest dest_ip ShareName ShareLocalPath RelativeTargetName AccessMask src_user | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `windows_alternate_data_stream_created_over_local_share_filter`
how_to_implement:To successfully implement this search, you need to be ingesting Windows Security Event Logs with EventCode 5145 enabled.
The Windows TA is also required.
Enable Object Access auditing (success/failure) for File Share in group policy so that RelativeTargetName and IpAddress are populated. known_false_positives:Backup, replication, or file-sync software may occasionally write alternate data streams over administrative shares.
Loopback (127.0.0.1) access to a local share is rare for legitimate software, tune by ShareName or src_user as needed for your environment. References: -https://www.cyderes.com/howler-cell/rogueplanet-windows-zero-day -https://www.threatlocker.com/blog/nightmareeclipse-releases-new-poc-shieldbreak-exploits-same-weakness-as-rogueplanet drilldown_searches: name:'View the detection results for - "$dest$"' search:'%original_detection_search% | search dest = "$dest$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$dest$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['RoguePlanet']